Security: HKUDS/LightRAG
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Quadratic Regular Expression Denial of Service (ReDoS) in LightRAG’s Markdown image parserGHSA-8wpg-h5wf-jww4 published
Sep 5, 2026 by danielaskddModerate -
Uncaught Exception Denial of Service via __proto__ Entity Type in LightRAG WebUIGHSA-2xxv-6q6h-v72v published
Sep 5, 2026 by danielaskddModerate -
Persistent Denial of Service via Unvalidated Graph Attribute Injection in LightRAGGHSA-c922-pw4m-4wcv published
Sep 5, 2026 by danielaskddHigh -
Decompression bomb: a 200 KiB .docx expands without bound during parsingGHSA-2wpj-ffvv-2pq8 published
Sep 5, 2026 by danielaskddModerate -
Unauthenticated denial of service: `/api/chat` tokenizes an unbounded message on the event loopGHSA-r8jh-295g-vv42 published
Aug 9, 2026 by danielaskddHigh -
Decompression bomb: OOXML packages are expanded with no size or ratio budget in `_extract_xlsx` / `_extract_docx` / `_extract_pptx` and `export_embedded_image`GHSA-9p96-5j78-2f9x published
Sep 5, 2026 by danielaskddModerate -
Uncontrolled resource consumption: an unbounded `separators` list on `POST /documents/text` drives synchronous recursive chunking on the asyncio event loopGHSA-26pm-px5v-8c4w published
Aug 9, 2026 by danielaskddHigh -
Path traversal: a DOCX external image relationship `Target` reaches `_resolve_image_path` with no containment check, giving arbitrary local image readGHSA-8rgj-chc2-6chv published
Sep 5, 2026 by danielaskddModerate -
Authentication bypass: LIGHTRAG_API_PREFIX starting with /api collapses the default WHITELIST_PATHS into a blanket exemption for the entire APIGHSA-2hjx-23vw-wvw4 published
Jul 31, 2026 by danielaskddCritical